Information Security Statement
- Document ID
- APL-SEC-001
- Version
- 2.0
- Effective Date
- 29 June 2026
- Last Updated
- 16 July 2026
- Owner
- Aionpixel Technologies Private Limited
Aionpixel Information Security
- 1. Introduction
- 1.1 Purpose
- 1.2 Scope
- 1.3 Security Principles
- 2. Security Governance
- 2.1 Security Programme
- 2.2 Security Objectives
- 2.3 Shared Responsibility
- 3. Information Security Controls
- 3.1 Defence in Depth
- 3.2 Access Management
- 3.3 Authentication
- 3.4 Encryption
- 4. Infrastructure Security
- 4.1 Cloud Infrastructure
- 4.2 Network Security
- 4.3 Endpoint Security
- 5. Secure Software Development
- 5.1 Secure Development Practices
- 5.2 Change Management
- 5.3 Vulnerability Management
- 6. Security Monitoring
- 6.1 Operational Monitoring
- 6.2 Audit Logging
- 7. Backup and Business Continuity
- 7.1 Backup
- 7.2 Business Continuity
- 8. Security Incident Response
- 9. Third-Party Security
- 10. Responsible Security Disclosure
- 11. Continuous Improvement
- 12. Changes to this Statement
- 13. Contact Information
1. Introduction
1.1 Purpose
Aionpixel Technologies Private Limited ("Aionpixel", "we", "our", or "us") is committed to protecting the confidentiality, integrity, availability, and resilience of the information entrusted to us.
This Information Security Statement provides a high-level overview of the administrative, technical, and organisational measures adopted by Aionpixel to support the security of our corporate operations, digital services, and information assets.
This Statement is intended to provide transparency regarding our security governance while protecting confidential operational and technical security information.
1.2 Scope
This Statement applies to Aionpixel's corporate operations, including:
- the Aionpixel corporate website;
- corporate communication systems;
- business operations;
- customer engagement activities;
- recruitment processes;
- supplier interactions;
- corporate cloud services;
- internal business systems supporting corporate operations; and
- publicly accessible digital services operated by Aionpixel.
This Statement does not replace product-specific security documentation that may apply to individual software products or customer environments.
1.3 Security Principles
Our security programme is guided by the following principles:
- Security by Design
- Privacy by Design
- Defence in Depth
- Least Privilege
- Risk-Based Decision Making
- Accountability
- Operational Resilience
- Continuous Improvement
- Secure Development Practices
- Responsible Governance
These principles guide the design and operation of our corporate security programme.
2. Security Governance
2.1 Security Programme
Information security forms an integral part of Aionpixel's corporate governance framework.
Security considerations are incorporated into:
- corporate operations;
- software development;
- cloud services;
- customer engagement;
- supplier management;
- recruitment processes;
- business continuity planning; and
- organisational risk management.
2.2 Security Objectives
The objectives of our security programme include:
- protecting confidential information;
- maintaining information integrity;
- supporting service availability;
- reducing operational risk;
- supporting legal compliance;
- protecting customer trust;
- maintaining operational resilience; and
- continually improving our security maturity.
2.3 Shared Responsibility
Security is a shared responsibility.
Aionpixel
Responsible for:
- corporate governance;
- information security management;
- secure software development;
- infrastructure management;
- operational monitoring;
- incident response;
- supplier oversight; and
- continual security improvement.
Employees and Contractors
Responsible for:
- protecting confidential information;
- following internal security procedures;
- protecting authentication credentials;
- reporting suspected security incidents;
- maintaining professional confidentiality; and
- complying with corporate security requirements.
Business Partners
Business partners are expected to maintain security practices appropriate to the services they provide and to comply with applicable contractual security obligations.
3. Information Security Controls
3.1 Defence in Depth
Aionpixel applies multiple complementary security controls designed to reduce risk and strengthen protection.
Security controls may include:
- identity management;
- authentication;
- access control;
- encryption;
- network protection;
- application security;
- monitoring;
- audit logging;
- backup processes;
- incident response; and
- business continuity planning.
3.2 Access Management
Access to corporate systems is managed according to authorised responsibilities.
Security measures may include:
- role-based access;
- least-privilege principles;
- access reviews;
- account lifecycle management;
- authentication controls; and
- timely removal of unnecessary access.
3.3 Authentication
Authentication mechanisms are intended to protect authorised access to corporate systems.
Depending upon the system, authentication controls may include:
- secure password management;
- session management;
- account verification;
- password reset procedures;
- account lockout protections; and
- additional authentication measures where appropriate.
3.4 Encryption
Aionpixel seeks to protect information using appropriate encryption technologies.
Security controls may include:
- encrypted communications;
- encryption at rest where implemented;
- secure key management practices;
- certificate management; and
- secure cryptographic protocols.
Specific implementation details are not publicly disclosed for security reasons.
4. Infrastructure Security
4.1 Cloud Infrastructure
Aionpixel utilises professionally managed cloud infrastructure to support its corporate operations.
Infrastructure is selected to support:
- security;
- resilience;
- availability;
- scalability;
- operational continuity; and
- disaster recovery.
4.2 Network Security
Security controls may include:
- firewalls;
- secure network architecture;
- traffic monitoring;
- intrusion detection capabilities where implemented;
- network segmentation where appropriate; and
- operational monitoring.
4.3 Endpoint Security
Corporate devices are expected to be managed using appropriate security practices, including:
- operating system updates;
- security patches;
- endpoint protection;
- access controls;
- secure configuration; and
- device management practices where applicable.
5. Secure Software Development
5.1 Secure Development Practices
Security is incorporated throughout the software development lifecycle.
Development activities may include:
- secure coding practices;
- code review;
- dependency review;
- functional testing;
- regression testing;
- vulnerability assessment where appropriate;
- release management; and
- change control.
5.2 Change Management
Changes to corporate systems and software are managed through structured operational processes intended to minimise risk while supporting continual improvement.
5.3 Vulnerability Management
Aionpixel seeks to identify, assess, prioritise, and remediate security vulnerabilities affecting corporate systems.
Remediation priorities are determined according to factors including:
- severity;
- exploitability;
- operational impact;
- customer risk; and
- business priorities.
6. Security Monitoring
6.1 Operational Monitoring
Aionpixel operates monitoring processes intended to support:
- operational reliability;
- platform security;
- incident detection;
- fraud prevention;
- system health;
- performance monitoring; and
- business continuity.
6.2 Audit Logging
Corporate systems may maintain audit records relating to significant operational and security events.
Examples include:
- authentication events;
- administrative actions;
- configuration changes;
- security events;
- access management activities; and
- other operational events.
Audit information assists with security investigations, compliance, and operational accountability.
7. Backup and Business Continuity
7.1 Backup
Backup processes are maintained to support:
- disaster recovery;
- operational resilience;
- business continuity;
- authorised restoration activities; and
- protection against accidental data loss.
7.2 Business Continuity
Aionpixel maintains business continuity planning intended to minimise disruption arising from:
- infrastructure failures;
- cyber security incidents;
- communication failures;
- software defects;
- operational interruptions; and
- other unforeseen events.
Business continuity arrangements are reviewed periodically as organisational requirements evolve.
8. Security Incident Response
Aionpixel maintains processes intended to support:
- identification;
- assessment;
- containment;
- investigation;
- remediation;
- recovery; and
- post-incident review
of security incidents.
Where required by applicable law, affected parties and relevant authorities may be notified in accordance with legal obligations.
9. Third-Party Security
Where Aionpixel engages third-party providers, we seek to select organisations capable of supporting appropriate standards of:
- security;
- confidentiality;
- operational resilience;
- privacy protection; and
- contractual compliance.
Third-party providers are expected to protect information consistent with the services they perform.
10. Responsible Security Disclosure
Aionpixel encourages responsible reporting of legitimate security concerns affecting our corporate website or corporate services.
Individuals reporting security concerns should:
- act in good faith;
- avoid disrupting services;
- avoid accessing information without authorisation;
- provide sufficient technical information to support investigation; and
- allow Aionpixel reasonable opportunity to investigate before public disclosure.
Nothing in this Statement authorises penetration testing or security testing without prior written approval.
11. Continuous Improvement
Information security is an ongoing process.
Aionpixel continually reviews opportunities to strengthen its security programme through:
- technological improvements;
- operational enhancements;
- policy reviews;
- security awareness;
- process refinement;
- vulnerability remediation;
- supplier oversight; and
- evolving industry practices.
12. Changes to this Statement
This Information Security Statement may be updated periodically to reflect:
- changes in technology;
- organisational growth;
- legal developments;
- operational improvements;
- security enhancements; or
- other legitimate business requirements.
Updated versions will be published on the Aionpixel corporate website together with their effective date.
13. Contact Information
Questions relating to information security may be directed to:
Information Security TeamAionpixel Technologies Private Limited
Security enquiries:
Privacy enquiries:
General enquiries:
Corporate Website:
Annexure A – High-Level Security Framework
- Information Security Governance
- Identity & Access Management
- Secure Infrastructure
- Secure Software Development
- Monitoring & Audit Logging
- Backup & Business Continuity
- Incident Response
- Continuous Improvement
This diagram provides a simplified overview of Aionpixel's corporate information security framework and intentionally omits confidential implementation details.
Annexure B – Security Control Areas
| Security Domain | High-Level Controls |
|---|---|
| Governance | Security programme, policy management, accountability |
| Identity & Access | Role-based access, authentication, least privilege |
| Encryption | Encryption in transit, encryption at rest where implemented |
| Infrastructure | Cloud security, network protection, operational resilience |
| Software Development | Secure SDLC, change management, vulnerability management |
| Monitoring | Audit logging, operational monitoring, incident detection |
| Business Continuity | Backup, disaster recovery, continuity planning |
| Third-Party Security | Supplier assessment, contractual safeguards |
| Incident Response | Identification, containment, remediation, recovery |
| Continuous Improvement | Policy reviews, technology enhancements, security maturity |
Annexure C – Version History
| Version | Date | Description |
|---|---|---|
| 1.0 | 29th June 2026 | Initial Information Security Statement |
| 2.0 | 16th July 2026 | Comprehensive revision reflecting Aionpixel's expanded corporate operations, strengthened governance framework, enhanced security transparency, modern security practices, and alignment with the Corporate Privacy Policy, Terms of Use, and Cookie & Similar Technologies Policy. |